Chapter 3 IPS Filtering

Configure the Remote System Log Contact

STEP 1

STEP 2

STEP 3

CAUTION Remote syslog, in adherence to RFC 3164, sends clear text log messages using the UDP protocol with no additional security protections. Therefore, you should only use remote syslog on a secure, trusted network to prevent syslog messages from being intercepted, altered, or spoofed by a third party.

From the LSM menu, select IPS > Action Sets. Then, on the Action Sets page, click the Notification Contacts tab.

On the Notification Contacts page in the Contacts List, click the Remote System Log link.

On the Edit Notification Contact page, type the IP Address and Port for the host that receives the offloaded log messages.

STEP 4 Type the IP Address and Port for the host that will receive Remote System Log messages.

TIP Verify that the device can reach the remote system log server on your network. If the remote system log server is on a different subnet than the device management port you may have to add static routes (see “Static Routes” on page 159).

STEP 5

STEP 6 STEP 7 STEP 8 STEP 9

Select an Alert Facility and a Block Facility: none or select from a range of 0 to 31. These syslog number uses these numbers to identify the message source.

Select a Delimiter for the generated logs: tab, comma, semicolon, or bar. Click Add to table below to add the remote syslog server.

Enter a Remote system log aggregation period in minutes.

Click Save.

Configure the Management Console Contact

STEP 1

STEP 2 STEP 3 STEP 4

STEP 5

From the LSM menu, select IPS > Notification Contacts. Then, click the Notification Contacts tab.

Click the pencil icon next to the Management Console entry. Edit the Contact Name. By default, it is Management Console. Enter the Aggregation Period for notification messages in minutes.

Click Save.

Delete a Notification Contact

Note You cannot delete the default Remote System Log and Management Console contacts

STEP 1

STEP 2

From the LSM menu, select IPS > Action Sets. Then, click the Notification Contacts tab.

On the Notification Contacts page, click the Delete icon to remove the notification contact.

54 X Family LSM User’s Guide V 2.5.1